I ran the below query,
index=s sourcetype=S_1
| search Gene="dow" OR Gene="x" OR Gene="ari" OR Gene="lia" OR Gene="SX" OR Gene=z
| append [search index=s sourcetype="S_2"|fillnull |eval Gene="rage"]
| append [search index=s sourcetype=S_3 |fillnull|eval Gene="ork"]
| append [search index=s sourcetype=S_4|fillnull|eval Gene="tat"]
| append [search index=s sourcetype=S_5 | fillnull |eval Gene="bas"]
| append [search index=s sourcetype=S_6 | fillnull |eval Gene="bas1"]
| append [search index=s sourcetype=S_7|fillnull value=""|eval Gene="App"|fields *]
|rename Gene as General
| stats count by General,"Report"
|eventstats sum(*) as sum_* by General
|foreach * [eval "Status %"=round((count/sum_count)*100,2)]|rename count as Count
|fields - sum_count
|chart values("Status %") over "Report" by General
|sort "Report" desc
I expect the below Result,
But I get the below result, where "bas1" and "App" shows together as "OTHER"
And it happens after I use the chart command.
Anyone can help me out.
It's not the number of appends, it's the number of fields. By default, the chart command displays 10 fields and puts the rest into "other". To change that, use "| chart useother=f ...".
@richgalloway Still I face the same issue.